Server-Side Request Forgery Vulnerability in WeKnora Framework by Tencent
CVE-2026-30247

5.9MEDIUM

Key Information:

Vendor

Tencent

Status
Vendor
CVE Published:
7 March 2026

What is CVE-2026-30247?

The WeKnora framework, designed for advanced document understanding and retrieval, has a critical flaw in its 'Import document via URL' feature prior to version 0.2.12. This vulnerability allows for Server-Side Request Forgery (SSRF) through HTTP redirects, where attackers can exploit weaknesses in the framework's URL validation. Although the backend successfully blocks private IPs and loopback addresses, it fails to regulate redirect targets adequately. This oversight permits an attacker to execute a redirect chain that forces the server to access internal services, including unsecured Docker-specific internal addresses. The risk has been mitigated in version 0.2.12 with an important security update.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WeKnora < 0.2.12

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.